Hacker News new | past | comments | ask | show | jobs | submit login

It made the rounds in the press years ago. Here’s a first person account for ipsec, which was one of the first hits I found when looking for information about the SSL weakening:

https://www.mail-archive.com/cryptography@metzdowd.com/msg12...

It’s describing the same tactics, but a different protocol. Honestly, just crack open the SSL spec. In hindsight, it’s pretty obvious it was intentionally over-complicated.

The Wireguard protocol attempts to fix these issues by hardcoding everything behind a protocol version number. It’s vastly easier to implement and configure properly.




Join us for AI Startup School this June 16-17 in San Francisco!

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: